Double-Free Vulnerability in WatchGuard Fireware OS Affects VPN Processing
CVE-2026-19316
8.7HIGH
What is CVE-2026-19316?
A double-free vulnerability in the WatchGuard Fireware OS iked process poses a risk where remote unauthenticated attackers can exploit this flaw by sending specially crafted network traffic. This exploitation can lead to a Denial of Service condition, disrupting VPN processing and compromising network integrity. It is crucial for affected users to review the vendor advisory and implement security updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Fireware OS Default 2025.0 < 2026.2.2
Fireware OS Default 12.0 < 12.12.2
Fireware OS Default 2026.3 < 2026.3.1
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
McCaulay Hudson (@_McCaulay) of watchTowr
